Skip to content

Microsoft 365 security self-assessment

Microsoft 365 Security Self-Assessment Calculator

No tenant login, no Microsoft access, no admin consent, and not Microsoft Secure Score. Answer 12 core questions across 7 Microsoft 365 risk areas; the flow digs deeper only where answers look weak.

  • No login
  • No admin consent
  • Free
  • 12–18 questions
Question 1 of 120%
Control area 1 of 7
Identity & Access

Is strong MFA truly enforced for every privileged account?

Think Global Admin, Exchange Admin, Intune Admin, and similar privileged roles.

FAQ

About this Microsoft 365 security self-assessment

Short answers before you use the free Microsoft 365 security self-assessment.

Identity, mail, endpoint, sharing, app trust, monitoring and evidence controls across Microsoft 365.

Use the matrix first. It shows the weak control, the concern and the first fix.

Fix the highest exposure rows first, then line them up with Cyber Essentials readiness and operational risk.

Auditex is the free evidence tool. View the GitHub repository.

© 2026 Magrathean UK Ltd. All rights reserved.